Threat Intelligence

APT31 sets sights on Russian IT sector

China map outline, flag colors red, yellow glowing. Futuristic circuit board digital technology backdrop. High-tech data streams, innovation, modern design, connectivity global network.

Russian IT firms, particularly those contracted by the government, have been subjected to a stealthy wave of attacks from Chinese state-backed advanced persistent threat operation APT31 since last year, The Hacker News reports.

Intrusions launched by APT31, also known as Violet Typhoon, Judgment Panda, and PerplexedGoblin, involved multiple tools, including legitimate cloud services, such as Yandex Cloud, for command-and-control, the SharpADUserIP utility for reconnaissance, and SharpChrome.exe for browser cookie and credential compromise, according to an analysis from Positive Technologies.

APT31 also harnessed Microsoft dev tunnels, the Tailscale VPN, the SharpDir file-searching tool, and the Owawa credential-stealing IIS module, as well as the OneDriveDoor and CloudSorcerer backdoors that leveraged OneDrive and cloud services as C2, respectively. Additional payloads have also been distributed by APT31 through the COFFProxy backdoor, while the LocalPlugX malware enabled local network infections.

"APT31 is constantly replenishing its arsenal: although they continue to use some of their old tools... These tools and techniques allowed APT31 to stay unnoticed in the infrastructure of victims for years," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds